Reference🧭 Global overviewsIntermediate⏱ 26 min read

🛡️ Payment fraud by market

The dominant rail decides what fraud looks like: card-not-present fraud and strong authentication in the EEA, mandatory reimbursement of UK APP fraud, Brazil's MED, UPI and AePS in India, the absence of SCA in the US, and what published fraud rates are really worth

The rail determines the shape of fraud

A payment instrument's direction of flow refers to which party initiates the movement of funds: the payee or the payer. This distinction divides instruments into two families, each with its own form of fraud. A pull instrument, such as a card or a direct debit, authorizes the payee to draw funds using a credential held by the payer. The fraud consists of obtaining that credential and reusing it. The victim can still dispute the payment afterward. A push instrument, such as a credit transfer or an instant payment, requires the payer to issue the payment order personally, and the fraud consists of getting the payer to issue it. No bank credential is stolen.

Moving from one family to the other changes the problem that fraud prevention has to solve. On a pull rail, the problem remains technical: authenticate the cardholder, detect the compromised credential, handle the dispute. On a push rail, it becomes human, and the window for correction closes within seconds. The funds belong to the payee as soon as the payment settles. There is no chargeback. The only recourse is a recovery mechanism built from scratch by the regulator or the industry, and whether one exists varies from country to country.

RailDominant fraud typeReversibilityIndustry-wide countermeasureWho bears the loss by default
Card (pull)Credential theft, reused in card-not-present salesChargeback, within the time limits set by network rulesStrong authentication where the law requires it, tokenization, risk scoringIssuer or merchant, depending on the liability shift
Direct debit (pull)Misused mandate, unauthorized debitRefund at the debtor's request, within the scheme's time limitMandate checks, lists of authorized creditorsThe creditor, through reversal of the debit
Instant payment (push)Payer manipulation, fake payeeNone: the payment is final at settlementPayee verification before sending, limits, payment delaysThe payer, unless a dedicated reimbursement regime applies
Account-based wallet (push)Account takeover, then outbound transferNone on the resulting transferSecure enrollment, device change detectionThe payer, unless the provider is proven at fault
What the dominant rail demands of fraud prevention
$33.4B
global payment card fraud losses in 2024, down 1.2%
Nilson Report, January 2026
€4.2B
payment fraud reported in the European Economic Area in 2024
EBA / ECB, 2025 Report on Payment Fraud, December 2025
$20.9B
losses reported to the FBI's IC3 in 2025, from 1,008,597 complaints
FBI, 2025 Internet Crime Report
£1.28B
payment fraud losses in the UK in 2025
UK Finance, Annual Fraud Report 2026
🔑
The first question to ask
The direction of flow of the dominant payment method, pull or push, shapes a market's fraud prevention. A pull-payment market spends on cardholder authentication and dispute handling. A push-payment market spends on payee verification and on holding payment orders back. A system designed for cards and transplanted unchanged onto an instant payment rail checks the payer's identity. But on that rail, the fraud lies in the payment order the payer issues personally.

Europe: card-not-present sales account for most card fraud

The second Payment Services Directive (PSD2) requires every payment service provider in the European Economic Area to report the fraud it detects. The European Banking Authority (EBA) and the ECB aggregate these reports and publish them by half-year; the latest edition, released December 15, 2025, covers 2024. No other region collects payment fraud data under a regulatory reporting mandate with comparable coverage.

€4.2B
total fraud reported in the EEA in 2024, versus €3.5 billion in 2023
EBA / ECB, 2025 Report on Payment Fraud
€2.5B
credit transfer fraud in 2024, a rate of 0.001% of value
EBA / ECB, 2025 Report on Payment Fraud
€1.3B
fraud on cards issued in the EEA in 2024, a rate of 0.033%
EBA / ECB, 2025 Report on Payment Fraud
83 %
of card fraud involves remotely initiated payments
EBA / ECB, 2025 Report on Payment Fraud, 2024 data

Card-not-present (CNP) payments are card payments initiated without the card being physically presented to the merchant. In the European Economic Area, they account for 28% of card transaction value and 18% of card transaction volume, yet they carry 83% of card fraud, by value and by volume. Relative to the amounts processed, the fraud rate on the remote channel reaches 0.091%, versus 0.007% for card-present payments. That is 13 times higher by value, and 22 times higher by number of transactions.

SegmentShare of payments (value)Share of fraud (value)Fraud rate
Card-present72 %17 %0,007 %
Card-not-present28 %83 %0,091 %
Cross-border, all counterparties18% to 27%, depending on the periodabout 70% of card fraudmore than seven times the domestic rate
Cross-border, counterparty outside the EEA–30% of card fraud17 times the domestic rate
Card fraud in the EEA in 2024, by segment (EBA / ECB, 2025 Report on Payment Fraud)
⚠️
“One-leg-out” transactions are the gap in Europe's framework
A “one-leg-out” transaction has only one end inside the European Economic Area. Strong customer authentication does not apply to it: PSD2 requires SCA only when both payment service providers are established in the EEA. The fraud rate on these transactions is 17 times the domestic rate, and the segment accounts for 30% of European card fraud by value (EBA / ECB, 2024 data). A merchant that opens an acceptance channel outside the EEA, or that receives large volumes of cards issued outside it, will see that rate in its own network ratios. Segmenting by country of issuance isolates the segment running at 17 times the domestic rate, and that split should drive how the scoring budget is allocated.

Strong customer authentication (SCA) combines at least two independent factors from the categories of knowledge, possession, and inherence. Its coverage varies widely by instrument. In 2024, it applied to about 77% of the value of electronic credit transfers, but to only 40% of the number of electronic card payments and 38% of e-money transactions (EBA / ECB, 2024 data). In-person contactless payments explain most of the gap, because the low-value and cumulative-limit exemptions apply to them constantly. By transaction count, most European card payments are therefore still made without strong authentication.

ℹ️
Who bears the loss, and why the gap is structural
The user-borne share is the portion of fraud losses left for the customer to bear, with the rest absorbed by the payment service provider. In 2024, payment service users bore 38% of card fraud losses in the EEA. The share was 53% for direct debits and cash withdrawals, and 26% for e-money. For credit transfers, it reached 85% (EBA / ECB, 2024 data). The gap between 38% and 85% is the accounting expression of the difference between a pull instrument, which comes with a dispute right, and a push instrument, which does not. The spread across countries is just as wide: for cards, the user-borne share ranges from 12% to more than 87% depending on the member state.

The fraud rate on European credit transfers remains very low. The amount lost to fraud, however, is growing fast: it reached €2.5 billion in 2024, up 16% from 2023. Its makeup changed over the same period. Payer manipulation rose from 65% to 74% of the value of credit transfer fraud between 2023 and 2024, and from 55% to 71% of its volume. Most of the value lost to credit transfer fraud now comes from payment orders that payers issued themselves, under manipulation.

UK: APP fraud and the world's only mandatory reimbursement regime

The UK has run an instant payment rail, the Faster Payments Service, since 2008. It is a Pay.UK scheme, with Vocalink as the technical operator. The rail predates the euro area's instant payment sending mandate by 17 years, so the UK has had that whole period to observe the fraud that comes with it. Authorized push payment (APP) fraud is a payment that the payer makes after being deceived. The UK named it, measured it, and regulated it before any other market.

£576.4M
APP fraud losses in the UK in 2025, up 19%
UK Finance, Annual Fraud Report 2026
248 070
APP fraud cases in 2025, out of more than 4 million confirmed fraud cases
UK Finance, Annual Fraud Report 2026
£703.4M
unauthorized fraud losses in 2025, down 5%
UK Finance, Annual Fraud Report 2026
£221.5M
investment fraud losses alone, up 40%
UK Finance, Annual Fraud Report 2026

The Financial Services and Markets Act 2023 required the Payment Systems Regulator (PSR) to introduce reimbursement for victims. Section 71(2) defines a qualifying case as a payment order executed over Faster Payments as a result of fraud or dishonesty. The regulator implemented the requirement through a Specific Requirement addressed to Pay.UK and three Specific Directions, one of which extends the regime to CHAPS. It covers payments executed on or after October 7, 2024. Reimbursement is therefore a legal obligation enforceable against each provider in scope, not a voluntary industry commitment.

ParameterRuleWhat it requires of the provider
ScopeFaster Payments and CHAPS, between two UK accounts, including payments initiated through a PIS providerNo other payment system is in scope
Cap£85,000 per claimSet aside provisions and document the policy applied above the cap
Cost sharing50/50 between the payer's provider and the payee's providerReceiving funds puts a price on the quality of your onboarding
ExcessOptional, £100 maximum, cannot be applied to vulnerable customersThe split is always calculated as if the excess had been applied
DeadlineFive business days, or up to 35 if more information is requestedInvestigate, decide, and give written reasons within the deadline
Time limit13 months after the last payment in the claimKeep fraud data for the full required period
Who is coveredConsumers, microenterprises, and charitiesScope modeled on that of the Financial Ombudsman Service
Out of scopeCards, international payments, other payment systems, civil disputesA customer whose goods never arrived from a legitimate seller is not an APP victim
The mandatory reimbursement regime, parameter by parameter (PSR, consolidated policy PS25/5, May 2025)
⚠️
Two reimbursement rates, and the gap between them is the story
Two reimbursement rates circulate for the UK, and they cover different scopes. Across all APP losses in 2025, UK firms reimbursed £354.3 million, or 61% (UK Finance, 2026). Within the scope of the mandatory regime alone, the Payment Systems Regulator reports £316 million reimbursed out of £358 million in in-scope losses, or 88%. That figure covers October 7, 2024, to March 31, 2026. The gap between the two rates reflects cases that the regime does not cover but that the industry statistic still counts. Of 438,300 claims reported, only 301,500 were in scope. The rest fall under general law.
How an APP fraud claim is handled
Customer
Reports the fraud to the sending provider
Without delay once aware, and no later than 13 months after the last payment in the claim
Sending provider
Notifies the receiving providers within two hours
Rule 4.1 of the Faster Payments reimbursement rules; a suspicious activity report is also filed if money laundering is suspected
Sending provider
Investigates the claim on its own
It gathers the evidence, including from the receiving provider, and can stop the five-day clock while it obtains missing information
Sending provider
Reimburses or declines, in writing, with reasons
A refusal must rest on first-party fraud by the customer or on gross negligence, and neither ground applies to vulnerable customers
Receiving provider
Pays its 50% share to the sending provider
Within the deadline set by the scheme rules, and capped under Specific Requirement 1

Before reimbursement comes into play, the industry-wide countermeasure is Confirmation of Payee. Run by Pay.UK, it compares the name the payer enters with the name on the destination account, before the transfer is executed. The regulator imposed it on the six largest banking groups through Specific Direction 10, with a deadline of March 31, 2020. Specific Direction 17 extended it to around 400 more providers, with deadlines of October 31, 2023, and October 31, 2024. Five years of operation have revealed four recurring problems: trading names that differ from the legal name, joint accounts, accounts held on behalf of third parties, and false positives that erode payer vigilance.

🔑
The collection account name is an operational setting
The name on a merchant's collection account must exactly match the name the customer enters, or the name the checkout page pre-fills. A legal entity that collects payments under a trading name different from its registered name will get a string of “no match” responses. Warned that the names don't match, payers often abandon the payment and call the company's customer service instead. Confirm the registered name with the account-holding bank before launching the payment channel. The same requirement applies in the euro area, where Verification of Payee has been mandatory on all credit transfers since October 9, 2025.

Brazil: Pix, irrevocability, and a recovery mechanism added after launch

Pix is Brazil's instant payment system, run by the Banco Central do Brasil (BCB) on the SPI infrastructure since November 2020. In five years, it has become the country's leading retail payment method. The rail processed 79.8 billion transactions worth R$35.36 trillion in 2025, and accounted for 54.7% of retail transactions in the second half of 2025 (BCB). A Pix payment is irrevocable once it settles. The rail had no dispute procedure at launch, so consumer protection was built after it went live.

The Mecanismo Especial de Devolução (MED), or special return mechanism, is the recovery procedure imposed on all Pix participants since 2021. The victim contacts their own bank, which has the funds still held by the recipient blocked and then returned. The Banco Central do Brasil publishes every deadline in the procedure: claims can be filed up to 80 days after the payment, analysis takes 7 days, the return request 72 hours, and execution 6 hours (Guia MED, Banco Central do Brasil). Funds that had already left the receiving account were beyond the reach of the original mechanism.

November 2020
Pix launches
Addressing by chave (CPF/CNPJ, phone number, email, random key), mandatory EMVCo QR code, and participation required for every institution with more than 500,000 accounts.
2021
MED goes live
Blocking and return of funds in cases of fraud or operational failure, limited to the first receiving account.
Second half of 2025
Pix becomes the majority rail
Pix carries 54.7% of Brazilian retail transactions (Banco Central do Brasil).
February 2026
MED 2.0 becomes mandatory
Precautionary blocking extends beyond the first receiving account, along the chain of recipient accounts (Banco Central do Brasil).
⚠️
The MED is not a chargeback, and confusing the two is costly
The Banco Central do Brasil explicitly limits the scope of the MED. The procedure covers fraud and operational failures, not commercial disputes. A customer unhappy with a delivery has another route: asking the merchant for a refund, which the merchant issues itself through the Pix API. A customer service team that sends these customers to their bank generates inadmissible claims, slows resolution, and drags down satisfaction scores. The line between fraud and civil disputes also concerns the UK regulator, whose reimbursement regime excludes customers whose goods never arrived from a legitimate seller.

The main vector for Pix fraud remains social engineering aimed at the payer: fake sellers, altered QR codes, fake customer service, physical coercion. MED 2.0 addresses the most common workaround, which is moving funds immediately to a second and then a third mule account. Precautionary blocking now follows that chain. An institution that receives disputed funds therefore faces blocks on its own account, and the quality of its sub-merchant onboarding becomes part of its financial risk.

  • Separate MED claims from commercial refund requests from the first contact: they differ in deadlines, point of contact, and outcome.
  • Track the MED claim rate by sub-merchant: that metric triggers blocking, not revenue.
  • Document the onboarding of every receiving account: an unidentifiable recipient exposes the institution to fund returns and penalties.
  • Never promise reversibility in a checkout flow paid with Pix: the rail offers none, and the promise creates a legally false expectation.

India: UPI, AePS, and friction as public policy

Unified Payments Interface (UPI) is India's retail instant payment infrastructure, run since 2016 by the National Payments Corporation of India (NPCI) under a mandate from the Reserve Bank of India. The rail processed 241.62 billion transactions worth ₹314 lakh crore in fiscal 2025-26 (NPCI). Merchant payments on UPI are free for most volumes. Zero fees, instant execution, addressing by virtual ID, and openness to third-party apps all widen the rail's attack surface. The fraud consists of getting the account holder to authorize a payment, with no need to steal any bank credential.

241.62B
UPI transactions in fiscal 2025-26, up 30% by volume
NPCI
10 114
fraud cases reported by Indian banks and financial institutions in fiscal 2025-26, involving ₹48,021 crore
Reserve Bank of India, Annual Report 2025-26, May 2026
23 722
cases reported in the previous fiscal year, involving ₹32,803 crore: more cases, much smaller amounts
Reserve Bank of India, Annual Report 2025-26
₹5 000
limit applied during the first 24 hours of a new UPI ID or a newly linked account
NPCI, UPI rules

The Aadhaar Enabled Payment System (AePS), run by the NPCI since 2011, supports cash withdrawals, deposits, balance inquiries, and payments by fingerprint at a banking correspondent, with no card or phone needed. The rail underpins financial inclusion in rural India. It is also the country's best-documented fraud vector: identity theft, biometric harvesting, and fraud by the touchpoint operator itself. That last risk stems from the operator's position: the operator enters the customer's Aadhaar number and captures their fingerprint during the transaction.

On June 27, 2025, the RBI issued the directions Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators (RBI/2025-26/63), in force since January 1, 2026. They require acquiring banks to carry out full due diligence on every touchpoint operator: Aadhaar, PAN (India's tax ID) or an equivalent document, and business details. Banks must also monitor transactions continuously and apply risk-based controls (location profiling, velocity limits). The directions apply to all commercial banks, regional rural banks, and cooperative banks, as well as to the NPCI itself.

ℹ️
Friction as a deliberate policy tool
The RBI's 2025-26 annual report says it is studying the deliberate introduction of friction into payment journeys to counter authorized transaction fraud. It also lists a second workstream: a universal mechanism to immediately block all debits on an account, across every digital channel. Both run counter to the ever-shorter payment journeys that accompanied UPI's growth. An issuer or aggregator operating in India should therefore expect to add verification steps to its journeys, not remove them.

The same shift is under way elsewhere in Asia. Since December 16, 2024, Singapore has applied a Shared Responsibility Framework issued by the MAS and the IMDA. Losses from phishing scams are shared among the financial institution, the telecom operator, and the consumer. Compensation is due only if one of the first two breached a duty assigned to it. A deceived consumer therefore bears the loss unless a breach is proven. Hong Kong hit the same problem as early as 2018: a few weeks after the Faster Payment System launched, the HKMA suspended wallet top-ups while the flaws it had found were fixed. PromptPay in Thailand, QRIS in Indonesia, DuitNow in Malaysia, and PayNow in Singapore all raise the same question of who bears the loss, and each market has answered it differently.

US: no strong authentication, and liability rules that vary by instrument

The US has no strong authentication requirement for payers. Federal law has no equivalent of PSD2, so there are no exemptions to document and no fraud-rate threshold to stay under to keep the right to skip authentication. Using 3-D Secure is a business decision, made transaction by transaction. In Europe, the operational goal is to minimize the number of challenges the regulation imposes. In the US, it is to determine when triggering a challenge is justified.

$20.877B
losses reported to the FBI's IC3 in 2025, up 26% year over year
FBI, 2025 Internet Crime Report
$3.047B
business email compromise (BEC) losses in 2025, from 24,768 complaints
FBI, 2025 Internet Crime Report
191 561
phishing and spoofing complaints in 2025, the top category by number
FBI, 2025 Internet Crime Report
$7.7B
losses reported by victims aged 60 and over, from 201,266 complaints
FBI, 2025 Internet Crime Report

US federal consumer protection rests on two separate regimes, and which one applies depends on the payment instrument. Regulation Z covers credit cards, while Regulation E (12 CFR 1005) covers debit cards and electronic fund transfers. The cardholder's liability depends on how quickly the loss is reported: $50 within two business days, $500 after that. There is no cap at all on transactions that appear on a statement and are reported more than 60 days after it was sent. Network rules sit on top of both regimes and allocate losses among financial institutions. The merchant has no rights of its own under them: it remains a third party to the relationship between the cardholder and their bank.

InstrumentApplicable regimeUnauthorized transactionTransaction authorized under manipulation
Credit cardRegulation ZCardholder liability capped at $50Out of scope; recourse limited to network rules
Debit cards and electronic fund transfersRegulation E (12 CFR 1005)$50 within two business days, $500 after that, unlimited after 60 daysOut of scope: the customer authorized the transaction
Zelle, RTP, FedNow (push credit)Regulation E, for unauthorized transfers onlySame scheduleNo dedicated federal protection to date
ACHNacha rules, supplemented by Regulation E for consumersReturn windows by SEC codeNo automatic reversal
What US federal law protects, instrument by instrument

US law has not settled who bears the loss when a customer personally authorizes a transaction under manipulation. In December 2024, the CFPB sued Early Warning Services and three of its bank owners, seeking reimbursement for this kind of induced fraud on Zelle. The network handled 4.2 billion transactions worth more than $1.2 trillion in 2025 (Early Warning Services, February 2026). The CFPB dropped the case on March 4, 2025, with prejudice. The New York State Attorney General took up the case on August 13, 2025, in New York state court. With the federal regulator out, the question now rests with the states, and the applicable rule depends on where the case is brought.

⚠️
Nacha's 2026 rules shift the burden to the receiving bank
Nacha is phasing in monitoring requirements for credit-push fraud in two waves. The first takes effect on March 20, 2026, for originating institutions, originators, third-party senders, and third-party service providers that exceeded six million entries in 2023. The second takes effect on June 19, 2026, for all receiving institutions and the rest of the market, regardless of volume. No federal law addresses manipulation fraud, so the obligation comes from the network rules. It puts the detection burden on the institution receiving the funds, the same principle the UK adopted for splitting reimbursement costs.

Vishing, spoofing, and social engineering cut across every market

Social engineering covers the techniques a fraudster uses to get a person to carry out a transaction themselves. These techniques appear in every market, and the dominant rail doesn't change how they play out. The lures arrive by email (phishing), text message (smishing), or phone call (vishing): three channels serving the same goal. The first phase gathers identifying details: a name, a balance, a recent transaction, an order number. The second phase replays those details over the phone, to make the caller credible and get the victim to execute the transfer.

Anatomy of a bank impersonation scam
Collection
Harvesting identifying details
Data breaches, fake parcel-tracking sites, fake government forms, or lists bought on criminal marketplaces
Hook
Text message or notification about a suspicious transaction
A spoofed sender ID mimics the bank; the message asks the victim to call back, or warns that a call is coming
Call
The fraudster calls from a number that displays as the bank's
*Caller ID spoofing* turns a stranger into a trusted contact
Pressure
Creating urgency and authority
The script keeps the victim from hanging up to check; it also supplies the words to reassure the bank's fraud team
Execution
The victim authenticates the transaction personally
Biometric approval in the banking app, a code read aloud, or a transfer keyed in under dictation to a supposed “safe account”
Dispersal
The funds move through a chain of mule accounts
On an instant rail, the time between execution and the first hop is measured in seconds, which is what Brazil's MED 2.0 targets
🏦
Bank impersonation
The dominant scenario on credit transfer rails. Strong authentication makes no difference: the victim is the one who authenticates, apparently fully aware.
📄
Supplier impersonation fraud
An email posing as a supplier announces a change of bank details. The target is the accounts payable team, not an individual. The FBI classifies these cases as business email compromise: $3.047 billion reported in 2025.
🛒
Purchase scams
A fake listing, with payment requested off-platform on a rail with no reversibility. This scam is the most common by number of cases in the UK: 71% of APP fraud cases in 2025 (UK Finance, 2026).
🎙️
Synthetic voices and faces
In 2025, the FBI introduced an “AI-related” descriptor: 22,364 complaints and $893 million in reported losses. Recognizing an executive's voice no longer counts as a control.

Regulators disagree on who should bear the loss. The UK places it on payment providers, split equally between the sending and receiving firms. Singapore allocates it in a cascade, and only when a breach is proven. Brazil allocates it to no one and focuses on recovering the funds. The US leaves it with the payer once the payer has authorized the transaction. Because the party bearing the loss differs in each regime, the four lead to four different ways of sizing the fraud budget and organizing customer service.

MarketInstruments coveredWho bears the lossLaw or mechanism
United KingdomFaster Payments, CHAPSPayment providers, 50/50 between sending and receiving firms, capped at £85,000Financial Services and Markets Act 2023; PSR, PS25/5
SingaporeRetail credit transfersCascade: financial institution, then telecom operator, then consumerShared Responsibility Framework, MAS and IMDA, December 16, 2024
BrazilPixNo one: recovery of funds still in the accountMecanismo Especial de Devolução, Banco Central do Brasil
United StatesZelle, RTP, FedNow, ACHThe payer: the transaction was authorizedRegulation E (12 CFR 1005); state litigation pending
Euro areaSCT and SCT InstThe payer in principle; prevention upfrontRegulation (EU) 2024/886: Verification of Payee mandatory since October 9, 2025
Four liability doctrines for payer manipulation fraud
🔑
What actually protects against manipulation
Authentication confirms that the payment order really comes from the account holder, and payer manipulation doesn't defeat that check. The countermeasures that reduce this fraud therefore work outside authentication. They include checking the payee's name before sending, delaying the first transfers to a new payee, and capping amounts in the first 24 hours. Others detect abnormal sessions and interrupt a payment journey while a phone call is in progress. A tougher 3-D Secure challenge strengthens cardholder authentication, so it does nothing against manipulation fraud.

Fraud rates compared, and what they leave out

A fraud rate divides a fraudulent amount or number of transactions by a reference base, and its value depends as much on the numerator as on that base. Comparing two national rates requires three things to line up, and they rarely do. First, scope. European reporting covers every payment service provider by law, while US statistics include only what victims reported to the FBI. Second, the denominator: a rate may be calculated on value, on volume, or only on transactions by domestic issuers. Third, the triggering event. Some figures count net losses, others gross losses, and others blocked attempts.

ScopePublished indicatorValueWhat the figure leaves out
European Economic AreaFraud reported by providers under PSD2, 2024€4.2 billion, including €2.5 billion in credit transfers and €1.3 billion in cards (EBA / ECB, 2025)Blocked attempts; fraud the victim never reported to their provider
European Economic AreaCard fraud rate, 20240.033% of value; 0.091% for card-not-present (EBA / ECB, 2025)Cards issued outside the EEA and used in Europe
United KingdomPayment fraud losses, 2025£1.28 billion, including £576.4 million in APP fraud (UK Finance, 2026)Fraud suffered outside the reporting members
United StatesComplaints received by IC3, 2025$20.877 billion from 1,008,597 complaints (FBI, 2025)Anything not reported to the FBI: this is a complaint database, not a market measure
Global, cardsPayment card fraud losses, 2024$33.4 billion, down 1.2% (Nilson Report, January 2026)Non-card instruments, including all manipulation fraud on credit transfers
AustraliaCard-not-present share of card fraudNearly 85% of fraud on Australian cards (Australian Payments Network)Non-card instruments; the country has no general strong authentication requirement
Public fraud indicators and what they cover
⚠️
Three misreadings, all found in industry documents
Adding up the EEA, the UK, and IC3 produces a meaningless total, because it combines two regulated reporting measures with a database of voluntary complaints. Comparing a card fraud rate with a credit transfer fraud rate sets 0.033% against 0.001% without accounting for average transaction size. Credit transfers carry far larger amounts than card payments, and that denominator mechanically crushes any rate calculated by value. Concluding from a low card fraud rate that a market is safe ignores the ongoing shift to push instruments. In the EEA, the card fraud rate holds steady while payer manipulation grows from 65% to 74% of the value of credit transfer fraud.
  • Who reports, and under what obligation? A regulated report and a voluntary complaint are never comparable.
  • Which denominator? Value or volume: the ratio between the two varies by a factor of two to three depending on the instrument.
  • What triggers the count? Net loss after recovery, gross loss, or blocked attempt? Three figures for the same event.
  • Which year, and which publication date? Fraud data comes out 12 to 18 months after the fact; a figure presented as recent often describes the year before last.

What an operator has to manage, market by market

An enforceable threshold is a level above which a third party, whether a card network or a regulator, takes action against the party being measured. Two kinds of thresholds coexist. Card network thresholds penalize the merchant and apply wherever cards are accepted, with values that vary by region. Regulatory thresholds penalize the payment provider and change from country to country, so no single policy can work for an operator active in several markets.

ProgramCalculationThresholdConsequence
Visa VAMP(TC40 fraud + TC15 disputes) / TC05 settled transactions“Excessive” merchant threshold lowered from 2.2% to 1.5% on April 1, 2026, in Europe, the US, Canada, and Asia-Pacific; 2.2% retained in CEMEANotification, remediation plan, fees on excess transactions
Mastercard ECMchargebacks in the month / transactions in the previous monthAt least 100 chargebacks and a ratio of at least 1.5%Notification, remediation plan, fines that escalate the longer the merchant stays in the program
Mastercard HECMsame calculationAt least 300 chargebacks and a ratio of at least 3%Higher fines, pressure from the acquirer, risk of termination
Thresholds that trigger card network penalties

Regulatory obligations differ by market. The same payment journey launched in six countries falls under six liability regimes and six sets of mandatory controls. The list below sums up, market by market, what to work through before opening a payment channel.

  • EEA: strong authentication by default, with exemptions to document; the transaction risk analysis exemption is lost if the requesting provider's fraud rate exceeds 0.13%, 0.06%, or 0.01%, depending on the value band (PSD2 RTS). Verification of Payee mandatory on all credit transfers since October 9, 2025.
  • UK: mandatory reimbursement of APP victims on Faster Payments and CHAPS, split 50/50, capped at £85,000, within five business days. Confirmation of Payee mandatory for around 400 providers.
  • Brazil: MED mandatory for every Pix participant, with blocking extended along the chain of recipient accounts since MED 2.0.
  • India: mandatory due diligence on AePS touchpoint operators since January 1, 2026; ₹5,000 limit during the first 24 hours of a new UPI ID.
  • US: no authentication requirement; Nacha credit-push fraud monitoring required from March 20 and then June 19, 2026.
  • Singapore: anti-scam duties assigned to financial institutions and telecom operators, with compensation due only if a duty is breached (MAS and IMDA, since December 16, 2024).
  • Australia: no general strong authentication requirement; the Australian Payments Network framework applies only to merchants exceeding A$50,000 in losses and a 0.2% fraud rate for two consecutive quarters.
🔑
The order of work, in any market
1. Identify the dominant rail and its direction of flow, pull or push. 2. Determine whether a reimbursement regime exists, and who funds it. 3. Segment the fraud rate by channel, by country of issuance, and by whether authentication was applied, because an overall average can't show where losses come from. 4. Measure the time between transaction and report, which determines whether funds can be recovered at all on an instant rail. 5. Treat onboarding quality as a financial risk item, since at least three regulators now make the receiving institution pay.